Race in pickle.dumps/loads per-interpreter cache leaks references
未关闭
还没有人认领这个 Issue。
interpreter-core
topic-subinterpreters
type-bug
- 主要语言
- Python
- 星标
- 77.2k
- 派生
- 35.9k
- PR 合并指标
- PR 指标待抓取
描述
Bug report
Bug description:
PyObject *dumps = state->pickle.dumps;
if (dumps != NULL) {
return dumps;
}
dumps = PyImport_ImportModuleAttrString("pickle", "dumps");
if (dumps == NULL) return NULL;
state->pickle.dumps = dumps;
return dumps;
This is a check-then-act race. Two threads in the same interpreter can both run this code:
- Thread A reads state->pickle.dumps → NULL
- Thread B reads state->pickle.dumps → NULL
- Thread A imports pickle.dumps, holds a strong reference R_A
- Thread B imports pickle.dumps, holds a strong reference R_B
- Thread A stores R_A into the slot
- Thread B stores R_B into the slot, overwriting R_A
Now the slot owns R_B, and R_A is leaked forever.
CPython versions tested on:
CPython main branch
Operating systems tested on:
macOS
Linked PRs
- gh-149002
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从报告中所示的每个解释器对 pickle.dumps 和 pickle.loads 的缓存访问开始,然后检查链接的 PR gh-149002,以了解已经在进行的工作。验证并发初始化和引用所有权;完成的标准是该竞争条件不再泄漏引用。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- backend
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100